generated: '2026-07-27' method: searched probe: true description: >- AEMO publishes an RFC 9116 security.txt at https://www.aemo.com.au/.well-known/security.txt naming its Cyber Security Team as the reporting channel. There is no public bug bounty (no HackerOne / Bugcrowd / Intigriti program was found) and no published safe-harbour or coordinated-disclosure policy document; the security.txt carries a Contact and a Hiring field only — no Policy, Encryption, Preferred-Languages or Expires field. contact: - mailto:cybersecurity@aemo.com.au policy: [] bug_bounty: none security_txt: url: https://www.aemo.com.au/.well-known/security.txt status: 200 file: well-known/aemo-security.txt fields_present: - Contact - Hiring fields_missing: - Policy - Expires - Encryption - Preferred-Languages - Acknowledgments - Canonical evidence: - source: https://www.aemo.com.au/.well-known/security.txt kind: security.txt status: 200 detail: 'Contact: mailto:cybersecurity@aemo.com.au' - source: well-known/aemo-security.txt kind: harvested-file related: - name: Australian Energy Sector Cyber Security Framework (AESCSF) note: >- AEMO administers the AESCSF on behalf of the Australian energy sector. It is a sector-wide maturity framework AEMO runs for others, not a certification of AEMO's own API platform, and it is recorded here as context rather than as an AEMO compliance claim. url: https://www.aemo.com.au/-/media/files/initiatives/cyber-security/aescsf/aescsf-quick-reference-guide.pdf gaps: - No published vulnerability-disclosure policy page or safe-harbour statement. - security.txt has no Expires field, which RFC 9116 requires.